Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-47615

30
FAUCET Score

CVE-2024-47615 is a critical Out-of-Bounds Write vulnerability affecting GStreamer, a media-handling library. Specifically, the gst_parse_vorbis_setup_packet function in vorbis_parse.c fails to validate input size, leading to memory corruption. This flaw has a CVSS score of 9.8 (Critical), indicating it can be exploited remotely without authentication, resulting in high impact to confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and limited media coverage. The issue is fixed in GStreamer version 1.24.10.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.24.10CPE matchmatch criteria
cpe:2.3:a:gstreamer:gstreamer:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.6HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.13%
Probability of exploitation in next 30 days
EPSS Percentile
63.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0113 is in the 49th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (21)

9001patch availablevia llm_extracted
View patch
gatsbyjspatch availablevia llm_extracted
View patch
joinmastodonpatch availablevia llm_extracted
View patch
mariadbpatch availablevia llm_extracted
View patch
nodejspatch availablevia llm_extracted
Fixed in: 25.4.0
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: gstreamer1-plugins-base-0:1.16.1-3.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: gstreamer1-plugins-base-0:1.16.1-3.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: gstreamer1-plugins-base-0:1.16.1-3.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: gstreamer1-plugins-base-0:1.16.1-3.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: gstreamer1-plugins-base-0:1.16.1-3.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: gstreamer1-plugins-base-0:1.10.4-3.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: gstreamer1-plugins-base-0:1.22.1-3.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: gstreamer1-plugins-base-0:1.18.4-7.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: gstreamer1-plugins-base-0:1.18.4-7.el9_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: gstreamer1-plugins-base-0:1.22.1-3.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: gstreamer1-plugins-base-0:1.16.1-3.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 Extended Lifecycle SupportFixed in: gstreamer1-plugins-good-0:1.10.4-3.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gstreamer1-plugins-base-0:1.16.1-5.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: gstreamer1-plugins-base-0:1.16.1-2.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: gstreamer1-plugins-base-0:1.16.1-3.el8_4
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: gstreamer1-plugins-base

Vendor Advisories (6)

nodejsllm-nodejs-9e1762a1939f642dCRITICAL

Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025

Aug 6, 2025
gatsbyjsllm-gatsbyjs-d2a2db116f1afcf5CRITICAL

HP ThinPro 8.1 SP6 Security Updates

Mar 3, 2025
9001llm-9001-fecf0327d92708b9CRITICAL

HP ThinPro 8.1 SP6 Security Updates

Mar 3, 2025
joinmastodonllm-joinmastodon-9b2d3b3c900c6299CRITICAL

HP ThinPro 8.1 SP6 Security Updates

Mar 3, 2025
mariadbllm-mariadb-7e20cc2309665f3eCRITICAL

HP ThinPro 8.1 SP6 Security Updates

Mar 3, 2025
redhatCVE-2024-47615Important

gstreamer1-plugins-base: out-of-bounds write in Ogg demuxer

Dec 11, 2024

References

lists.debian.org / debian-lts-announce/2024/12/msg00021.html
gitlab.freedesktop.org / gstreamer/gstreamer/-/merge_requests/8038.patch
Patch
gstreamer.freedesktop.org / security/sa-2024-0026.html
Release Notes
securitylab.github.com / advisories/GHSL-2024-115_GHSL-2024-118_Gstreamer
Third Party Advisory